AWS logging and Monitoring

Overview

Cloudtrail: auditing and API activity

Cloudwatch: Monitoring

Cloudwatch detail

Creating a custom metric in EC2

Event example

Cloudtrail Detail

Audit log for resource changes.
Create a trail, that delivers log files to S3 bucket.
Enables governance, compliance, operational risk auditing

AWS Config

Rules examples:

Remediation actions:

There are lots, including e.g.

Gives you a file per resource in S3